Skip to content

Legal

Privacy Policy

What we collect, why we collect it, who it is shared with, how long it is kept, and how to make us delete it.

Last updated

This Privacy Policy explains how Heirloom Journey (“Heirloom”, “we”, “us”) handles personal information when you use the Heirloom mobile application, this website and the services behind them (together, the “Service”).

Heirloom exists to hold a family’s private memories. That purpose sets the boundary for everything below: we collect what the Service needs in order to work, and nothing we would have to justify to you afterwards.

The short version

  • We do not sell or rent personal information, and we never have.
  • We do not serve advertising and do not share your information with advertising networks or data brokers.
  • We do not use your photos, videos, audio or captions to train machine-learning models, ours or anyone else’s.
  • Your memories are visible only to the people you choose. Private Vault contents are visible to nobody but you.
  • You can export your content and delete your account from inside the app, without asking us for permission.

This summary is for orientation only. The sections below are the operative terms.

1. Who is responsible for your information

Heirloom Journey is the controller of the personal information described in this policy. You can reach us at privacy@heirloom.setrick.com or by post at:

Heirloom Journey
[Registered address — line 1]
[City, region, postal code]
[Country]

2. What we collect

2.1 Information you give us

CategoryWhat it includesWhy we need it
Account detailsEmail address and/or phone number, a display name, and a password (stored only as a one-way hash — we never hold the password itself)To create your account, sign you in, and recover access if you lose it
ProfileOptional profile photo and short bioSo your family recognises you in a journey
Your memoriesPhotos, videos, voice recordings, titles, captions, dates and any comments or reactions you addThis is the content the Service exists to store and show to the people you chose
Private VaultMedia you place in your Vault, and a separate Vault passcode (again stored only as a one-way hash)To keep this content locked behind a second credential, visible to nobody else
Family and journey structureWhich families you belong to, which journeys you are in, who you invited, and private nicknames you give other membersTo enforce who can see what, and to show the right people the right content
Support correspondenceThe content of messages you send us, and the app version and device you sent them fromTo answer you and to reproduce problems

2.2 Information collected automatically

CategoryWhat it includesWhy we need it
Session and security dataAuthentication tokens, sign-in timestamps, counts of failed sign-in and failed Vault unlock attempts, and temporary lockout timesTo keep you signed in and to stop somebody guessing their way into your account
Technical dataIP address, device model, operating system version, app version, languageTo deliver the Service, diagnose faults and detect abuse
Activity within your circleWhich memories you have viewed (so “new” badges are accurate) and when content was added or changedTo show unread indicators and keep a journey in order
Push notification identifierA device subscription identifier, if you enable notificationsTo deliver the notifications you asked for

2.3 Device permissions

The app asks for these permissions when — and only when — you use the feature that needs them. Declining a permission disables that feature and nothing else.

  • Camera — to take a photo or record a video inside the app.
  • Microphone — to record a voice memory.
  • Photo library — to let you choose existing photos and videos to add. We receive only the files you select.
  • Biometrics (Face ID, Touch ID, fingerprint) — to unlock your Vault. This is handled entirely by your device’s operating system; we receive a yes-or-no result and never your biometric data.
  • Notifications — to tell you when someone adds to a journey you are in.

2.4 What we do not collect

  • We do not collect precise location. The app has no location permission.
  • We do not read your contacts or address book.
  • We do not track you across other companies’ apps or websites.
  • We do not use third-party advertising identifiers.
  • We do not intentionally collect special-category data (health, biometric identifiers, religious or political beliefs). If such information appears in a photograph you upload, it is processed only as ordinary content you chose to store.

3. How we use your information

We use personal information only for these purposes:

  • To provide the Service: storing your memories and showing them to the people you chose.
  • To authenticate you and keep your account and Vault secure.
  • To deliver the notifications you have turned on.
  • To answer support requests.
  • To keep the Service working and safe — diagnosing crashes, measuring aggregate reliability, detecting abuse and enforcing our Terms.
  • To meet legal obligations and to establish, exercise or defend legal claims.

We do not use your content for profiling or automated decision-making that produces legal or similarly significant effects on you.

Where the UK GDPR or EU GDPR applies, we rely on the following legal bases under Article 6(1):

PurposeLegal basis
Providing the Service you signed up forPerformance of a contract — Art. 6(1)(b)
Account security, abuse prevention, service reliabilityLegitimate interests — Art. 6(1)(f)
Push notifications; access to camera, microphone and photo libraryConsent — Art. 6(1)(a), withdrawable at any time in your device settings
Retaining records we are required to keepLegal obligation — Art. 6(1)(c)

5. Who your information is shared with

We do not sell personal information. We share it only in these circumstances:

5.1 The people you choose

Content you add to a journey is visible to the members of that journey. Content in a shared vault is visible to the members of that vault. Content in your private Vault is visible to nobody but you. You control these memberships from inside the app, and you can change them at any time.

5.2 Service providers

We use a small number of processors, each bound by contract to process personal information only on our instructions and to protect it appropriately:

Provider roleWhat they process
Cloud hosting and databaseAll Service data, at rest and in processing
Object storage (S3-compatible)Your photos, videos and audio files, held in private, non-public buckets
Transactional emailYour email address, to send verification, password reset and support messages
Push notification deliveryA device subscription identifier and the notification text, if you enable notifications
Apple App Store / Google PlayPurchase, install and crash information governed by Apple’s and Google’s own privacy policies, not ours

5.3 Legal and safety disclosures

We may disclose information where we are legally required to, or where it is necessary to protect the rights, property or safety of users or the public. We will notify you of a legally compelled disclosure unless we are prohibited from doing so.

5.4 Business transfers

If Heirloom is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account first.

6. International transfers

Our providers may process data in countries other than your own. Where personal information is transferred out of the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with additional safeguards where necessary.

7. How long we keep things

DataRetention
Account and profileUntil you delete your account
Your memories and Vault contentsUntil you delete them, or until you delete your account. Content you contributed to a shared journey may remain visible to that journey’s other members — see the deletion page
BackupsDeleted content is purged from backups within 30 days
Security logsUp to 12 months, then deleted or aggregated
Support correspondenceUp to 24 months after the request is resolved
Records we must keep by lawFor the period the relevant law requires

8. Security

We protect personal information with measures appropriate to its sensitivity, including encrypted transport (HTTPS/TLS), one-way hashing of account and Vault passwords, private object storage served through short-lived signed links, separate throttling of sign-in and Vault unlock attempts, and invalidation of every existing session when a password changes. Our Security page describes these in more detail, including what we do not claim.

No service can guarantee absolute security. If a breach affects your personal information and is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where required, within 72 hours.

9. Your rights

Depending on where you live, you may have some or all of the following rights. We honour these requests regardless of whether the law where you live compels us to.

  • Access — a copy of the personal information we hold about you.
  • Correction — to fix information that is inaccurate or incomplete.
  • Deletion — to have your account and content erased. See Delete your data.
  • Portability — a machine-readable copy of information you provided.
  • Restriction and objection — to limit or object to processing based on our legitimate interests.
  • Withdraw consent — at any time, without affecting processing already carried out.
  • Complain — to your local supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.

Exercise any of these by emailing privacy@heirloom.setrick.com. We will respond within 30 days, and will tell you if we need longer because the request is complex. We will not charge you, and we will not treat you differently for asking.

9.1 California residents

Under the CCPA/CPRA you have the rights to know, delete, correct, and to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. In the preceding twelve months we have not sold or shared personal information as those terms are defined by the CCPA, and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16. The categories we collect and the purposes we collect them for are listed in sections 2 and 3 above.

10. Children

Heirloom is not directed to children under 13, and we do not knowingly collect personal information from them. Families frequently store photographs of children — that content is provided by the adult account holder, who is responsible for having the right to share it. Our Children’s Privacy page sets this out in full, including how a parent or guardian can ask us to remove a child’s information.

11. Cookies and this website

The Heirloom mobile app uses no advertising or analytics cookies. This website uses only what is strictly necessary to serve the pages you request. See the Cookie Policy.

12. Changes to this policy

We may update this policy as the Service changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights or how we use your information, we will give you notice in the app or by email before it takes effect, and where the law requires it we will ask for your consent.

13. Contact

Privacy questions and requests: privacy@heirloom.setrick.com
Anything else: support@heirloom.setrick.com